4 ms·
I honestly don't think anyone that I'd be able to talk to on the phone there cares. Between the 4 or 5 people they passed me around to, I was given info about
by matmann2001 10y ago
I honestly don't think anyone that I'd be able to talk to on the phone there cares. Between the 4 or 5 people they passed me around to, I was given info about this other person that they had no right to give out.
And that's the lesson here. Customer support representatives are so far removed from positions where they can actually be helpful, that all they are able to provide anymore is apathy and canned responses.
- fencepost 10y agoThat's why I phrased it as I did. I'm pretty sure that by sending his bills (presumably containing information on procedures performed, ICD10 detailed diagnosis codes, etc.) this could be considered a breach. Obviously it covers fewer than 500 individuals and the matching names is a complicating factor, but I believe that they're still required to report it to HHS within the first 2 months of 2018, and to notify the other person. Assuming that their training is worth anything at all, getting a supervisor and saying "I believe there's been a HIPAA violation and I need to know who to talk to" should get IMMEDIATE attention - it goes beyond application of a clue-by-four and should immediately get you connected to their Compliance Officer. That person should have all sorts of motivation to get things straightened out so it's not an ongoing breach with further disclosures post-notification. The other kicker is that I believe the rules changed recently such that if an individual reports a breach and it results in fines, that individual may now receive part of the penalty amount (caveat: I didn't find a citation for this, just have heard it discussed somewhere). My guess is that in your case with a matching name it's unlikely that there'd be anything like that, but just the prospect of the headaches involved should motivate people to resolve the situation.